DEA-C01 Data Security and Governance Practice Question
A company uses AWS Lake Formation to manage data lake permissions. The data engineer notices that a user with SELECT permission on a table can also query the underlying data in Amazon S3 directly. How can the engineer enforce that access to the S3 data is only through Lake Formation?
⚠ Common exam trap
The trap is assuming that granting Lake Formation permissions automatically overrides or supersedes IAM — in reality IAM and Lake Formation are additive, and any direct S3 IAM allow defeats LF governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Grant the user permissions only through Lake Formation and remove any IAM policies that allow direct S3 access to the data location
Lake Formation permissions are enforced only when the caller accesses data through a Lake Formation-integrated engine (Athena, Redshift Spectrum, EMR, Glue). If the user also has IAM permissions on the underlying S3 path, they can bypass Lake Formation entirely by reading S3 directly. The fix is to remove those direct S3 IAM permissions so the only path to the data is through Lake Formation-governed services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use S3 Access Points with a policy that restricts access to only Lake Formation
Why it's wrong here
S3 Access Points cannot distinguish Lake Formation-mediated requests from direct S3 calls, since both arrive as ordinary S3 traffic; a bucket policy denying access unless requests come through Lake Formation is required. Access Points are tempting for scaling many applications' access to shared datasets.
- ✓
Grant the user permissions only through Lake Formation and remove any IAM policies that allow direct S3 access to the data location
Why this is correct
Lake Formation permissions govern only requests routed through Lake Formation; direct S3 GETs are authorised by IAM. Removing IAM policies that permit s3:GetObject on the data location closes that bypass, so the user's only viable path to the data is via Lake Formation's credential vending.
- ✗
Enable S3 Block Public Access on the bucket
Why it's wrong here
Block Public Access only blocks public and cross-account anonymous access; the user's direct S3 calls are authenticated and permitted by IAM, so it changes nothing. It is tempting as a broad S3 hardening control, and would be correct when the risk is accidental public exposure of bucket data.
- ✗
Change the S3 bucket policy to deny all access except from Lake Formation
Why it's wrong here
A bucket policy cannot distinguish Lake Formation-mediated access from direct S3 calls, because both arrive as ordinary S3 API requests from the same IAM principal; only disabling public bucket access and revoking direct S3 permissions, or using Lake Formation credential vending, enforces the boundary. Bucket policies suit restricting access by network origin or principal.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DEA-C01 question from scratch — 1,321 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DEA-C01 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DEA-C01 exam.